The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the activello_activate_plugin and activello_deactivate_plugin functions in the inc/welcome-screen/class-activello-welcome.php file missing capability and security checks/nonces. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins installed on a vulnerable site.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Activello | Colorlib | * | 1.4.2 (excluding) |
Bonkers | Colorlib | * | 1.0.6 (excluding) |
Illdy | Colorlib | * | 2.1.7 (excluding) |
Newspaper_x | Colorlib | * | 1.3.2 (excluding) |
Pixova_lite | Colorlib | * | 2.0.7 (excluding) |
Shapely | Colorlib | * | 1.2.9 (excluding) |
Affluent | Cpothemes | * | 1.1.2 (excluding) |
Allegiant | Cpothemes | * | 1.2.6 (excluding) |
Brilliance | Cpothemes | * | 1.3.0 (excluding) |
Transcend | Cpothemes | * | 1.2.0 (excluding) |
Antreas | Machothemes | * | 1.0.7 (excluding) |
Medzone_lite | Machothemes | * | 1.2.6 (excluding) |
Naturemag_lite | Machothemes | * | 1.0.4 (including) |
Newsmag | Machothemes | * | 2.4.2 (excluding) |
Regina_lite | Machothemes | * | 2.0.6 (excluding) |